RSS Amplifier

Risk Factor - Dr. Andrew G. Huff · Aug 12, 2026

When the Hospital Goes Dark

0
Sign in to vote or save

Dr. Andrew G. Huff · Risk Factor - Dr. Andrew G. Huff

Epidemiologist. Security engineer. Former Q-cleared scientist, Sandia National Laboratories. Ph.D. in Environmental Health Science, Emerging Infectious Disease and Epidemiology, DHS Center of Excellence Research Fellow. Former U.S. Army infantryman.

Four parts of this series have described systems that could hurt people. This one describes a system that already has, and it is the only part where I can give you effect sizes from the published literature rather than reasoning from architecture.

It is also the part where the counting problem becomes the whole problem. Nobody dies of ransomware. People die of a myocardial infarction that was treated forty minutes late, of a sepsis case caught on the second look instead of the first, of a stroke that arrived at a hospital already absorbing another hospital’s patients. The cause of death on the certificate is never the intrusion, and that is precisely why the intrusion has been cheap.

Six judgments, each with my confidence on a 0 to 100 scale.

1. Ransomware at a hospital increases in-hospital mortality for patients already admitted when the attack begins. This is now a published, quantified finding rather than an inference. High confidence, 88.

2. The magnitude is on the order of a one-third increase. Moderate to high confidence, 80, and the uncertainty is in the estimate rather than in the direction.

3. The harm extends to hospitals that were never attacked, through diversion and surge. This is the most important finding in the recent literature and the least discussed. High confidence, 85.

4. The deaths are real and essentially uncountable at the level of the individual patient. Both halves of that sentence matter, and people who want a body count and people who want to deny one both get this wrong. High confidence, 92.

5. No American ransomware death has been established as such in an individual case through a legal or medico-legal process. High confidence, 85. This is a statement about the evidentiary process, not about whether anyone has died. High confidence, 90.

6. Health care is where the casualties from every other sector’s failure arrive, which makes it the correct place to end the technical arc of this series. High confidence, 90.

The discipline for this part is the one I was trained in before any of the rest: you do not need to identify the individual to establish the excess.

Begin with the methodological problem, because everything else in this piece depends on understanding it.

Suppose a hospital is hit on a Tuesday. The electronic health record goes down. Imaging results stop crossing the network and start crossing the building on paper. Medication reconciliation reverts to a clipboard. The emergency department goes on diversion and ambulances are routed elsewhere. Elective procedures are canceled. Staff who spent their careers in a system where the chart is on a screen are now practicing without one.

Three weeks later, a patient who was admitted that Tuesday dies. What killed them?

Clinically, something specific and nameable. Sepsis. A cardiac event. A pulmonary embolism. That is what goes in the record, and it is not a lie. It is simply not the whole causal chain, and there is no field on the form for the part of the chain that includes a criminal group in another country.

This is the classic problem of a diffuse exposure with a delayed and non-specific outcome, and epidemiology has a standard answer for it, which is to stop trying to adjudicate individuals and start comparing populations. You take mortality at attacked hospitals against mortality at comparable hospitals that were not attacked, or against the same hospital before and after, and you look for a difference that survives adjustment for case mix. You are not asking which patient died because of the attack. You are asking how many more died than would have.

That is exactly the design used in the excess mortality work on heat waves, on air pollution, and on hurricanes, where the same objection is always raised and always answered the same way. Nobody’s death certificate says hurricane. The excess is real anyway, and it is measurable.

For years the honest position on ransomware and patient harm was that the mechanism was obvious and the evidence was thin. That is no longer the honest position.

In-hospital mortality. Research published in the American Economic Journal: Economic Policy in February 2026 found that in-hospital mortality for patients already admitted when an attack begins rises by roughly 34 to 38 percent. Related work puts the increase at about 33 percent during ransomware incidents and translates it into an estimate on the order of dozens of preventable deaths across a five-year period in the studied population.

Take a moment with the structure of that finding rather than the number. The population is patients who were already in the building. They did not choose the hospital after the attack. They were not diverted to it. They were lying in a bed when the systems went down, which makes them about as clean a natural experiment as this subject will ever produce. Whatever is driving the effect is happening to people whose care was already underway.

Cardiac arrest survival. The sharpest single result comes from the study of a four-hospital attack in San Diego County in 2021. Survival with a favorable neurologic outcome for out-of-hospital cardiac arrest fell from 40.0 percent before the attack to 4.5 percent during it and returned to 41.2 percent afterward.

Read that sequence carefully, because the shape of it is what makes it persuasive. The rate falls when the attack starts and recovers when the attack ends. That is a dose-response relationship in time, and time-linked reversibility is one of the strongest causal signals available in observational data. It is the same reasoning that establishes a drug effect from a washout period.

And note what out-of-hospital cardiac arrest is. It is the most time-critical presentation in emergency medicine, where survival is measured against minutes of downtime and the chain of survival has no slack anywhere in it. If you wanted to design a sentinel indicator for whether a hospital system is functioning, you would choose approximately this.

Now the finding that changes the shape of the problem, and the one I would put in front of a hospital board that believes it has managed this risk.

When a hospital goes on diversion, its patients do not evaporate. They go to the hospitals around it, which did not plan for them, are not compensated for them, and were not attacked.

The published work on this is unambiguous. During attacks at nearby facilities, unaffected hospitals have shown cardiac arrest presentations rising on the order of 81 percent and suspected strokes on the order of 75 percent. A JAMA Network Open analysis of a 2021 four-hospital incident documented adjacent, uninvolved hospitals experiencing surges in emergency department volume, longer waits, and increased stroke code activations.

Three consequences follow, and each one breaks something that health care institutions currently believe.

Your risk is not your own. A hospital’s exposure to ransomware harm is not a function of its own security posture. It is a function of the security posture of every hospital within diversion distance. You can do everything right and still absorb the surge from the one that did not, and no amount of investment in your own perimeter changes that. This is a collective action problem masquerading as an IT budget line.

The measured harm is an underestimate. Nearly all of the mortality work looks at attacked hospitals. If a meaningful share of the harm lands on neighbors, then the studies that measure only the victim are measuring a fraction of the effect. Whatever the true excess is, it is larger than what has been published, and I would rather say that plainly than pretend the published figure is the ceiling.

Regional concentration is the exposure. In a metropolitan area with several independent hospital systems, one attack degrades the whole region’s capacity. In a rural area with one hospital and a ninety-minute drive to the next, there is no next hospital to surge into. Those are two different failure modes and neither is addressed by anything in current policy.

In February 2024, Change Healthcare, a payments and claims clearinghouse owned by UnitedHealth Group, was hit by ransomware. It is not a hospital. No patient was ever inside it. It sits in the middle of a very large share of American medical claims and prescription transactions.

The effects were felt across the country for months. Pharmacies could not verify coverage. Practices could not submit claims and therefore could not be paid. Small providers, which run on thin operating margins and short cash cycles, faced payroll without revenue. Some closed. Patients experienced it as a pharmacy counter saying the system is down.

This is the food system finding from Part IV arriving in health care, and it is worth naming the pattern explicitly because it is now the fourth time this series has hit it.

In every sector examined so far, the concentration that makes the system efficient is the same property that makes a single compromise national. Water is soft because it is fragmented. Food, payments, and telecommunications are soft because they are consolidated. Both structures produce a single point of failure. They just produce it at opposite ends of the scale.

And notice which layer was hit. Not the clinical systems. Not a device. The money. An adversary who cannot reach a ventilator can reach the mechanism that pays for the ventilator, and the clinical consequence arrives anyway, more slowly and with nobody’s name attached to it.

Now I have to take something away from my own argument, in the same way Part II did with Oldsmar.

In September 2020, ransomware struck University Hospital Düsseldorf in Germany. A woman requiring emergency treatment was diverted to another hospital roughly thirty kilometers away and died. The case went around the world as the first death caused by a cyberattack. German prosecutors opened an investigation into negligent homicide.

The investigation did not sustain the claim. Prosecutors ultimately concluded that the delay could not be established as the cause of death, because the patient’s condition was such that she would very likely have died regardless. The case was not the clean causal chain the headlines described.

I raise it for the same reason I raised Oldsmar. The most-cited example in a field is often the weakest one, the correction almost never travels as far as the original claim, and a reader who knows only the headline is carrying a false certainty that a competent opponent can use to discredit everything around it.

But now notice the asymmetry, because this is the part people get backwards. The failure of the Düsseldorf case does not weaken the mortality finding. It illustrates exactly why the population-level method was necessary in the first place. Individual causation in a hospital death is almost never establishable to a legal standard, which is why five years of trying to find the one provable case produced nothing, while the population studies produced a one-third effect. The absence of a courtroom-proven death is not evidence that nobody died. It is evidence that the courtroom is the wrong instrument.

A short section on mechanism, because the mortality number is more persuasive when you can see how it happens.

The record. Modern clinical practice is built on instant access to a longitudinal record. Allergies, current medications, recent imaging, prior admissions, baseline labs. Without it, a clinician is practicing on history and physical alone, in a population where a large fraction of patients cannot reliably report their own medication list. Every order becomes slower and every decision carries more uncertainty.

The interlocks. Barcode medication administration, computerized order entry with dose checking, and automated allergy and interaction warnings are not conveniences. They are the engineered controls that catch human error at a known rate. Reverting to paper does not return the system to a 1985 baseline, because the staff, the workflow, and the patient acuity are not from 1985. It removes the safety net from a system that was designed around having one.

Time. Nearly every acute pathway in medicine is a race. Door to needle in stroke. Door to balloon in myocardial infarction. Antibiotics within an hour in sepsis. These thresholds exist because outcome degrades measurably with delay, and the literature quantifying that degradation is enormous. Anything that adds minutes at scale converts directly into worse outcomes, and a hospital running on paper adds minutes to everything at once.

The people. Sustained manual operation is exhausting in a way that does not appear in any incident report. Attacks routinely run for weeks. Staff working double shifts under degraded conditions make more errors, and the effect compounds precisely when the institution most needs them sharp.

So the mechanism is not mysterious and it does not require anyone to attack a medical device. It requires only that a hospital be made slower and less certain for long enough. The mortality follows from that, and it follows quietly.

The strongest objections to what I have argued, and my answers.

“You cannot name a single American who died from a ransomware attack.” Correct, and I said so at 85 in the Bottom Line. I also cannot name a single American who died of the 1995 Chicago heat wave in the sense you mean, because attribution at the individual level is not how that harm was established either. Excess mortality is a real measurement with a mature methodology, and demanding a named individual is a demand that the harm be invisible.

“These are observational studies. Correlation, not causation.” Fair, and there is no randomized trial coming, because you cannot randomize hospitals to be attacked. What the observational work has is a time-linked, reversible effect that appears when the attack starts and disappears when it ends, in a population that was already admitted and could not self-select. That is about as strong as observational evidence gets, and medicine acts on weaker.

“One-third sounds too large. That would be obvious.” It was obvious, to the people inside those buildings. It was not visible in any aggregate statistic because nothing in the reporting architecture links a hospital’s mortality to a hospital’s IT status, and no regulator collects both. The effect was invisible for the same reason the water sector’s exposure was invisible: nobody was required to look.

“You are arguing for regulation of hospital IT.” In this part I am arguing for measurement, which has to come first. There is no mandatory linkage today between cyber incident reporting and clinical outcome data, which means the country cannot currently answer the question this piece is about using its own official statistics. That is fixable without a single new security mandate.

“Using Düsseldorf against your own case is a rhetorical trick.” It would be if I had buried it. I gave it a section, stated that prosecutors did not sustain the causal claim, and then argued that the failure of the individual case is the reason the population method exists. If that reasoning is wrong, it is wrong on the merits and not because of where I put it.

Part VI, “The Shield We Defunded.” The last part, and the only one about money. The warning was published on 7 April. The attacks came in late July. In between, the agency that issued the warning lost roughly a third of its workforce, and the two divisions cut hardest were the two whose job is to reach exactly the small utilities this series has been about. On 30 September the information sharing law expires and the water grant programs lapse, on the same day. I will show you the numbers, name what they buy and what they no longer buy, and end with the only thing in this series that is actually addressed to you.

[1] American Economic Journal: Economic Policy, February 2026, on hospital ransomware and in-hospital mortality for admitted patients. https://www.aeaweb.org/journals/pol

[2] Dameff C et al., “Ransomware Attack Associated With Disruptions at Adjacent Emergency Departments in the US,” JAMA Network Open, 2023. https://jamanetwork.com/journals/jamanetworkopen

[3] UC San Diego Center for Healthcare Cybersecurity, analysis of cardiac arrest outcomes during a regional ransomware attack. https://cyberhealth.ucsd.edu/

[4] TechTarget, “Studies show ransomware has already caused patient deaths,” summarizing the peer-reviewed literature. https://www.techtarget.com/searchsecurity/feature/Studies-show-ransomware-has-already-caused-patient-deaths

[5] CyberScoop, “Ransomware is driving an increase in emergency patient care.” https://cyberscoop.com/ransomware-attacks-health-care-emergency-visits-microsoft/

[6] US Department of Health and Human Services, Change Healthcare cybersecurity incident response and provider impact. https://www.hhs.gov/about/news/2024/03/05/hhs-statement-regarding-the-cyberattack-on-change-healthcare.html

[7] Reporting on the September 2020 University Hospital Düsseldorf ransomware incident and the subsequent prosecutorial finding on causation.

[8] American Heart Association, chain of survival and time dependence in out-of-hospital cardiac arrest. https://cpr.heart.org/

[9] Surviving Sepsis Campaign, hour-1 bundle and time to antibiotics. https://www.sccm.org/SurvivingSepsisCampaign/Home

[10] CDC, excess mortality methodology. https://www.cdc.gov/nchs/nvss/vsrr/covid19/excess_deaths.htm

[11] Health Sector Cybersecurity Coordination Center (HC3), threat briefs on ransomware in health care. https://www.hhs.gov/about/agencies/asa/ocio/hc3/index.html

[12] Joint Cybersecurity Advisory AA24-038A, PRC state-sponsored actors and US critical infrastructure, 7 February 2024. https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a

No posts

Read the original on aghuff.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.